Snews
by Solucija
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2010-2926 | 0.03 | — | 0.01 | Jul 30, 2010 | SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter. | |||
| CVE-2006-0715 | 0.03 | — | 0.02 | Feb 15, 2006 | Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field. | |||
| CVE-2005-3853 | 0.03 | — | 0.01 | Nov 27, 2005 | SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php. | |||
| CVE-2006-3916 | 0.00 | — | 0.01 | Jul 28, 2006 | Cross-site scripting (XSS) vulnerability in snews.php in sNews (aka Solucija News) 1.4 allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. | |||
| CVE-2006-0716 | 0.00 | — | 0.01 | Feb 15, 2006 | SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters. |
- CVE-2010-2926Jul 30, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter.
- CVE-2006-0715Feb 15, 2006risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.
- CVE-2005-3853Nov 27, 2005risk 0.03cvss —epss 0.01
SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php.
- CVE-2006-3916Jul 28, 2006risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in snews.php in sNews (aka Solucija News) 1.4 allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.
- CVE-2006-0716Feb 15, 2006risk 0.00cvss —epss 0.01
SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.